I was under the impression that Google Play Store apps were cryptographically signed by the developer/publisher (not by Google), and the phone would refuse to update the app if the key behind the signature had changed. Am I wrong on this?
Signal themselves aren't on f-droid which has far more protections and the apk download is basically hidden on their site.
Google certainly has no qualms about China, is draconian Australia much of a stretch?